Challenge Board

Browse the full target list

Log in to reveal challenge IPs.

🐀🐀🐀🐀

🧩 LDAP Lab · 2 Machines

CorpNet

A two-machine Active Directory lab. Enumerate the domain controller’s SMB shares and a vulnerable employee portal, then chain credential leaks across both machines to achieve full domain compromise.

OSCP Active Directory
Entry Point Hidden until login
Progress 0 / 2 rooted
🐀🐀🐀🐀🐀 🔒 Premium Only

🧩 LDAP Lab · 2 Machines

MegaCorp

A two-machine Active Directory lab focused on MS14-025 (GPP credential harvest). Start with an exposed backup config on the workstation, then pivot to the domain controller via SYSVOL to decrypt the service account password and achieve root.

OSCP Active Directory
Progress 0 / 2 rooted
🐀🐀🐀🐀🐀 🔒 Premium Only

🧩 LDAP Lab · 1 Machine

VaultNet

A three-machine Active Directory lab focused on network pivoting. Only the domain controller is exposed to the internet. Players must chain SMB credential harvesting on the DC, SSH tunnelling, unrestricted file-upload RCE on the internal web server, and MySQL credential extraction on the internal database to fully compromise all three machines.

OSCP Active Directory Pivoting
Progress 0 / 1 rooted
🐀🐀 🔒 Premium Only

Bindforge

Every enterprise has a directory. Bindforge's directory holds the full map of who has access to what — accounts, groups, and a few fields that the original engineer populated a little too liberally. It was only ever meant to be accessed from inside the building.

OSCP CPTS Database Active Directory
Progress - / -
🐀🐀 🔒 Premium Only

Rootbase

The Rootbase server has been the backbone of three different applications over five years. Each team that inherited it assumed the previous one had secured it properly. None of them checked.

OSCP Database
Progress - / -
🐀🐀🐀🐀 🔒 Premium Only

Keyspace

Keyspace was provisioned as a temporary caching layer during a product launch. The launch went well. The cleanup never happened. The server is still running, still reachable, and nobody on the current team knows its password — or whether it has one.

OSCP Database
Progress - / -
🐀🐀

Driftsync

Driftsync runs nightly, faithfully mirroring data from one machine to the next. The engineer who wrote the job configured it to be 'easy to use'. He was proud of how accessible he'd made it. That was two years ago.

OSCP Network File Shares
IP Hidden until login
Progress - / -
🐀🐀🐀 🔒 Premium Only

Bifrost

Bifrost was set up to bridge two legacy teams who couldn't agree on a file-sharing standard. So they ran both. Twice the surface, half the oversight. Somewhere in the middle of all that data lives a path forward.

OSCP CPTS Network File Shares
Progress - / -
🐀🐀

Walkabout

Walkabout is the network monitoring node that nobody monitors. It has a view of every device on the segment — interface stats, process lists, everything the ops team ever thought to wire up. It reports faithfully to whoever asks.

OSCP Network Enumeration
IP Hidden until login
Progress - / -
🐀🐀 🔒 Premium Only

Neuravex

Neuravex is CorpTech's shiny new internal AI assistant. The engineers shipped it fast, the executives loved it, and nobody asked too many questions about how it was built. It knows a lot. It's happy to talk. The question is how to make it tell you the right things.

Web
Progress - / -
🐀🐀🐀

Injectrix

The employee portal was built by a contractor in 2019, accepted without a security review, and has been quietly running ever since. It handles timesheets, leave requests, and a few internal tools nobody fully remembers adding. The codebase has never been audited.

OSCP CPTS Web
IP Hidden until login
Progress - / -
🐀🐀

Loophole

The document viewer was built over a long weekend to replace a tool that no longer worked. It went live on Monday. It has never been reviewed. The developer who built it is very proud of how quickly it shipped.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀

Sharehouse

The NFS server was set up to make file access easy across the team. It succeeded. It made access very easy. The engineer who configured it trusted the network perimeter to do the hard work — a decision that made sense at the time.

Network Privesc File Shares
IP Hidden until login
Progress - / -
🐀

Shellcast

The sysadmin who ran Shellcast was meticulous about backups. Every week, a snapshot. Every directory, archived. He never thought carefully about what those backups contained — or where they were stored.

Network
IP Hidden until login
Progress - / -
🐀🐀🐀🐀🐀 🔒 Premium Only

Darkpulse

Darkpulse is a full Active Directory environment built by an ops team that grew too fast to keep up with its own complexity. Every layer trusts the one beneath it. The monitoring system has a view of everything — and so will you, once you understand what it's reporting.

Web
Progress - / -
🐀🐀 🔒 Premium Only

🕐 Launching soon

In calculating...

Foxhole

Foxhole's authentication system was written by a developer who read the documentation, just not all of it. The gate looks solid from the outside. The question is whether you understand how the lock actually works.

Network
Progress - / -
🐀🐀🐀🐀 🔒 Premium Only

🕐 Launching soon

In calculating...

Tracewire

Tracewire's FTP server was used once, during a late-night maintenance window, by an engineer who was troubleshooting a network issue and capturing everything. The capture was archived. The archive was left on the server. The session contained more than just packet headers.

Network
Progress - / -
🐀🐀🐀

Tempest

Tempest is an internal reporting tool that the development team is quietly proud of. It renders fast, it looks clean, and it was built without once consulting the documentation on safe input handling.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀 🔒 Premium Only

Docparse

DocuParse processes invoices for an accounts team that needed automation fast. The developer who built it enabled every feature the XML library offered, valued flexibility, and shipped the Friday before a long weekend.

CPTS Web
Progress - / -
🐀🐀🐀 🔒 Premium Only

Jailkey

Jailkey is the authentication layer for a suite of internal tools. The team built it themselves rather than pulling in a dependency. They were thorough. They were careful. They just left one door open that they assumed nobody would find.

Web
Progress - / -
🐀🐀🐀🐀🐀

Hexvault

HexVault is a classified document management system used by a fictional intelligence contractor. It stores sensitive material, controls access carefully, and presents a surface that looks more hardened than it is. No single weakness hands you the keys — but every component has something it trusts a little too much.

Web
IP Hidden until login
Progress - / -
🐀

Codebleed

Codebleed runs the internal DevOps portal for a team that moves fast. The current deployment looks clean — polished, even. But software has a memory, and this server has been around long enough to have accumulated a history worth reading.

Web DevOps
IP Hidden until login
Progress - / -
🐀🐀🐀🐀 🔒 Premium Only

Capsule

Capsule is a data platform that was provisioned for a project, shipped on time, and handed to ops without a security checklist. The database is reachable. The data inside it is more useful than the team intended. And somewhere on this machine, a capability was granted that nobody thought to revoke.

Web
Progress - / -
🐀🐀🐀🐀 🔒 Premium Only

Debugtrap

Debugtrap is a Flask application running in an environment that was never quite finished. The developer tested locally, pushed to production, and moved on to the next feature. Somewhere between development and deployment, a setting that should have changed did not.

CPTS Web
Progress - / -
🐀🐀

StackDrop

StackDrop was built in a sprint by a developer who no longer works there. It does one thing: accept files from the build pipeline and make them available to the team. The handoff notes say it was hardened before go-live. The new team assumed that meant it was done.

Binary Exploit
IP Hidden until login
Progress - / -
🐀🐀🐀🐀🐀 🔒 Premium Only

DarkRat

r4tking built his own private operations platform — implant registry, remote probe, operator management. He thought it was locked down. Find the cracks, chain them together, and own the machine from web panel to root shell. Nothing here is accidental.

Progress - / -
🐀🐀🐀🐀🐀 🔒 Premium Only

Mirage

MirrorNet Corp ran a covert data intelligence platform. After their takedown, one server was left running. The admin swore it was hardened — 'everything real is behind another layer'. Dozens of researchers have tried. They all came back with flags. Every one of them was fake.

Progress - / -
🐀🐀

Axiom

The SolarGate incident team flagged unusual activity on prod-web-01. A file-upload vulnerability gave an attacker a foothold as www-data, and the logs show things escalated from there. Your job: step into the analyst's seat, reconstruct what happened, and finish the job the attacker started.

IP Hidden until login
Progress - / -
🐀

Inkblot

Inkblot runs an internal CMS built by someone who trusted their logs a little too much. The file inclusion is right there. What you put in the request is what ends up in the log. What ends up in the log ends up on the page.

IP Hidden until login
Progress - / -
🐀🐀

🕐 Launching soon

In calculating...

Blindspot

Blindspot is an internal URL validation tool. It checks whether endpoints are reachable — and it makes those requests from the server. There's an internal configuration service that wasn't supposed to be externally accessible.

IP Available at launch
Progress - / -
🐀🐀🐀

🕐 Launching soon

In calculating...

TokenSmith

TokenSmith is an internal OAuth 2.0 provider. It handles authorization flows and issues tokens to clients. There's a known issue in the tracker about redirect_uri validation — issue #214, filed months ago, still open.

IP Available at launch
Progress - / -
🐀🐀🐀🐀

🕐 Launching soon

In calculating...

Threadbare

Threadbare runs a privileged file integrity checker. It verifies that you own a file before reading it as root. The check and the read are two separate operations — and the filesystem doesn't stand still between them.

IP Available at launch
Progress - / -
🐀🐀🐀

Breakout

Breakout is an internal container management console that was meant to be ops-only. Someone left a debug endpoint live. The container has more access to the runtime than it should — and so do you.

IP Hidden until login
Progress - / -
🐀🐀

Shapeshifter

Shapeshifter is an internal developer profile service built with Node.js. It lets users update their profile data through a flexible merge endpoint — one that trusts deeply nested JSON a little too much.

IP Hidden until login
Progress - / -
🐀🐀🐀

Synapse

Synapse is an internal ML Model Hub that lets data science teams upload and share serialized model files. The platform loads every uploaded model automatically — trusting the data because trust is faster than validation.

IP Hidden until login
Progress - / -
🐀🐀🐀 🔒 Premium Only

NullSecurityX Lab

NullSecurityX runs an internal bug bounty triage platform. The dev team pushed source code to production with the .git directory intact. Three vulnerabilities to chain — none of them obvious until you look closely.

Web CPTS
Progress - / -
🐀 🔒 Premium Only

SolarGate

SolarGate Energy's solar monitoring server has a misconfigured Python binary and a web service that's a little too helpful. Foothold first, SUID second.

OSCP Privesc Web Project Meridian
Progress - / -
🐀 🔒 Premium Only

Meridian Hub

The Meridian central data hub runs a root-owned cleanup task every minute. Someone on the ops team made the script world-writable. They trusted the filesystem more than they should have.

OSCP Privesc Network Project Meridian
Progress - / -
🐀🐀 🔒 Premium Only

VoltCore

VoltCore's network diagnostics panel passes your input straight to ping. The sudo policy for the next hop is generous. Two steps to root.

OSCP Privesc Web Project Meridian
Progress - / -
🐀🐀 🔒 Premium Only

GridLock

GridLock's power management node runs awk as root for log analysis. The IT team didn't read the GTFOBins entry for awk. You did.

OSCP Privesc Project Meridian
Progress - / -
🐀🐀🐀 🔒 Premium Only

Apex

Apex is the hardest node in the SolarGate network. The document reader doesn't validate paths. Python has a capability it shouldn't. Chain them.

OSCP Privesc Web Project Meridian
Progress - / -

No challenges match the selected filters.

Want to learn the methodology behind these labs? The XSS Rat's Endless Bundle includes 45+ courses, CNWPP/CAPIE/CxWAP certs, weekly live sessions, and all future releases — 80% off right now.
Get the Bundle

☠ Infection Chain

Find hidden fragment codes scattered across machines and unlock The Burrow — a secret area for those who dig deep.

Enter The Burrow →